adwcleaner[r1]j

Upload: jse

Post on 17-Feb-2018

215 views

Category:

Documents


0 download

TRANSCRIPT

  • 7/23/2019 AdwCleaner[R1]j

    1/5

    # AdwCleaner v4.206 - Logfile created 15/06/2015 at 10:10:59# Updated 01/06/2015 by Xplode# Database : 2015-06-14.1 [Server]# Operating system : Windows 7 Home Premium (x86)# Username : Gonalo - GONALO# Running from : C:\Users\Gonalo\Downloads\AdwCleaner.exe# Option : Scan

    ***** [ Services ] *****

    Service Found : IHProtect ServiceService Found : ServiceEverything

    ***** [ Files / Folders ] *****

    File Found : C:\Program Files\Mozilla Firefox\browser\searchplugins\delta-homes.xmlFile Found : C:\Program Files\Mozilla Firefox\defaults\pref\itms.jsFile Found : C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\LocalStorage\hxxp_websearch.relevantsearch.info_0.localstorageFile Found : C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\LocalStorage\hxxp_websearch.relevantsearch.info_0.localstorage-journalFile Found : C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\LocalStorage\hxxp_www.delta-homes.com_0.localstorage

    File Found : C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\LocalStorage\hxxp_www.delta-homes.com_0.localstorage-journalFile Found : C:\Users\Gonalo\AppData\Roaming\LiveSupport.exe_log.txtFile Found : C:\Users\Gonalo\AppData\Roaming\Mozilla\Firefox\Profiles\samkhsc6.default\user.jsFile Found : C:\Users\Gonalo\AppData\Roaming\PDFShaper.iniFile Found : C:\Users\Gonalo\AppData\Roaming\regsvr32.exe_log.txtFile Found : C:\Users\Gonalo\AppData\Roaming\VVZXSYFile Found : C:\Users\Gonalo\AppData\Roaming\VVZXSY.exeFile Found : C:\Users\Gonalo\AppData\Roaming\XOSCEFile Found : C:\Users\Gonalo\AppData\Roaming\XOSCE.exeFile Found : C:\Users\Gonalo\daemonprocess.txtFile Found : C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Local Stor

    age\hxxp_en.softonic.com_0.localstorageFile Found : C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_en.softonic.com_0.localstorage-journalFile Found : C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_websearch.relevantsearch.info_0.localstorageFile Found : C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_websearch.relevantsearch.info_0.localstorage-journalFile Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_isearch.avg.com_0.localstorageFile Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_isearch.avg.com_0.localstorage-journalFile Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_websearch.relevantsearch.info_0.localstorage

    File Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_websearch.relevantsearch.info_0.localstorage-journalFile Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_isearch.avg.com_0.localstorageFile Found : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_isearch.avg.com_0.localstorage-journalFile Found : C:\Users\Vasco\AppData\Local\funmoods-speeddial.crxFile Found : C:\Users\Vasco\AppData\Local\Google\Chrome\User Data\Default\LocalStorage\hxxp_en.softonic.com_0.localstorageFile Found : C:\Users\Vasco\AppData\Local\Google\Chrome\User Data\Default\Local

  • 7/23/2019 AdwCleaner[R1]j

    2/5

    Storage\hxxp_en.softonic.com_0.localstorage-journalFile Found : C:\Users\Vasco\AppData\Local\Google\Chrome\User Data\Default\LocalStorage\hxxp_websearch.relevantsearch.info_0.localstorageFile Found : C:\Users\Vasco\AppData\Local\Google\Chrome\User Data\Default\LocalStorage\hxxp_websearch.relevantsearch.info_0.localstorage-journalFile Found : C:\Users\Vasco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jZip.lnkFile Found : C:\Windows\system32\RegistryHelperLM.ocxFolder Found : C:\Program Files\miuitabFolder Found : C:\Program Files\SupTabFolder Found : C:\ProgramData\{72725c86-aad7-02b9-7272-25c86aad721a}Folder Found : C:\ProgramData\Avg_Update_0814tbFolder Found : C:\ProgramData\IePluginServiceFolder Found : C:\ProgramData\IHProtectUpDateFolder Found : C:\ProgramData\Registry HelperFolder Found : C:\ProgramData\SoftWarehouseFolder Found : C:\ProgramData\StarAppFolder Found : C:\ProgramData\Tarma InstallerFolder Found : C:\ProgramData\WPMFolder Found : C:\Users\GONALO~1\AppData\Local\Temp\BrowseMarkFolder Found : C:\Users\GONALO~1\AppData\Local\Temp\jZipFolder Found : C:\Users\GONALO~1\AppData\Local\Temp\NetCrawlFolder Found : C:\Users\Gonalo\AppData\Local\genienextFolder Found : C:\Users\Gonalo\AppData\Local\globalUpdate

    Folder Found : C:\Users\Gonalo\AppData\Local\jZipFolder Found : C:\Users\Gonalo\AppData\Local\MobogenieFolder Found : C:\Users\Gonalo\AppData\LocalLow\AVG Secure SearchFolder Found : C:\Users\Gonalo\AppData\Roaming\goforfilesFolder Found : C:\Users\Gonalo\AppData\Roaming\newnext.meFolder Found : C:\Users\Gonalo\AppData\Roaming\SolvusoftFolder Found : C:\Users\Gonalo\AppData\Roaming\SupTabFolder Found : C:\Users\Gonalo\AppData\Roaming\sweet-pageFolder Found : C:\Users\Joana.GONALO\AppData\Local\jZipFolder Found : C:\Users\Me\AppData\Local\jZipFolder Found : C:\Users\Me\AppData\LocalLow\AVG Secure SearchFolder Found : C:\Users\Vasco\AppData\Local\FunmoodsFolder Found : C:\Users\Vasco\AppData\Local\jZip

    Folder Found : C:\Users\Vasco\AppData\LocalLow\AVG Secure SearchFolder Found : C:\Users\Vasco\AppData\Roaming\FunmoodsFolder Found : C:\Users\Vasco\Funmoods

    ***** [ Scheduled tasks ] *****

    Task Found : FunmoodsTask Found : GoforFilesUpdateTask Found : VVZXSYTask Found : VVZXSYTask Found : XOSCETask Found : XOSCETask Found : 0814tbUpdateInfo

    Task Found : 0814tbUpdateInfo

    ***** [ Shortcuts ] *****

    Shortcut Infected : C:\Users\Gonalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnkShortcut Infected : C:\Users\Gonalo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnkShortcut Infected : C:\Users\Gonalo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

  • 7/23/2019 AdwCleaner[R1]j

    3/5

    Shortcut Infected : C:\Users\Gonalo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

    ***** [ Registry ] *****

    Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command [(Default)] - "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1434056033&z=a8fc50012d6f09becfd6c80gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command [(Default)] - "C:\Program Files\Google\Chrome\Application\chrome.exe" hxxp://www.delta-homes.com/?type=sc&ts=1434056033&z=a8fc50012d6f09becfd6c80gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exehxxp://www.delta-homes.com/?type=sc&ts=1434056033&z=a8fc50012d6f09becfd6c80gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~1\SupTab\SEARCH~1.DLLKey Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}Key Found : HKCU\Software\AppDataLow\Software\CrossriderKey Found : HKCU\Software\AppDataLow\SProtectorKey Found : HKCU\Software\Appscion

    Key Found : HKCU\Software\BIKey Found : HKCU\Software\Conduit_Search_ProtectKey Found : HKCU\Software\GlobalUpdateKey Found : HKCU\Software\GoforFilesKey Found : HKCU\Software\InstallCoreKey Found : HKCU\Software\jZipKey Found : HKCU\Software\LiveSupportKey Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\delta-homes.comKey Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.comKey Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}

    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BF81DC48-60C0-40E8-BD6D-F97A743C6F33}Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A5A2A90-3

    B30-4E6E-A955-2F232C6EF517}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\jZipKey Found : HKCU\Software\SoftonicKey Found : HKCU\Software\WebplayerKey Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}

  • 7/23/2019 AdwCleaner[R1]j

    4/5

    Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}Key Found : HKLM\SOFTWARE\Avg Secure UpdateKey Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXEKey Found : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}Key Found : HKLM\SOFTWARE\Classes\CLSID\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}Key Found : HKLM\SOFTWARE\Classes\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}Key Found : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}Key Found : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}Key Found : HKLM\SOFTWARE\Classes\jZip.fileKey Found : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}

    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}Key Found : HKLM\SOFTWARE\delta-homesSoftwareKey Found : HKLM\SOFTWARE\GlobalUpdateKey Found : HKLM\SOFTWARE\GoforFilesKey Found : HKLM\SOFTWARE\IHProtectKey Found : HKLM\SOFTWARE\jZipKey Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}Key Found : HKLM\SOFTWARE\microsoft\shared tools\msconfig\startupreg\mobilegenidaemonKey Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd

    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppPath\jZip.exeKey Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-480333868Key Found : HKLM\SOFTWARE\Registry HelperKey Found : HKLM\SOFTWARE\SP GlobalKey Found : HKLM\SOFTWARE\SProtectorKey Found : HKLM\SOFTWARE\SupDpKey Found : HKLM\SOFTWARE\SupTab

    Key Found : HKLM\SOFTWARE\supWPMKey Found : HKLM\SOFTWARE\sweet-pageSoftwareKey Found : HKLM\SOFTWARE\Tarma InstallerKey Found : HKLM\SOFTWARE\VittaliaKey Found : HKLM\SOFTWARE\WpmKey Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServiceKey Found : HKLM\System\CurrentControlSet\Services\Eventlog\Application\registryhelper serviceKey Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\webcakeu

  • 7/23/2019 AdwCleaner[R1]j

    5/5

    pdaterKey Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WpmKey Found : HKU\.DEFAULT\Software\Avg Secure Update

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v9.0.8112.16476

    Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] - hxxp://search.delta-homes.com/web/?type=ds&ts=1434056033&z=a8fc50012d6f09becfd6c80gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592&q={searchTerms}Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.delta-homes.com/?type=hp&ts=1434056033&z=a8fc50012d6f09becfd6c80gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://search.delta-homes.com/web/?type=ds&ts=1434056033&z=a8fc50012d6f09becfd6c80gcz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592&q={searchTerms}Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.sweet-page.com/web/?type=ds&ts=1397490980&from=cor&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592&q={searchTerms}Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.delta-homes.com/?type=hp&ts=1434056033&z=a8fc50012d6f09becfd6c80g

    cz7ccz1ebw3q7e3c6z&from=ient06110&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.sweet-page.com/web/?type=ds&ts=1397490980&from=cor&uid=WDCXWD3200AAKX-001CA0_WD-WMAYUE28959289592&q={searchTerms}

    -\\ Mozilla Firefox v38.0.5 (x86 pt-PT)

    -\\ Google Chrome v43.0.2357.124

    [C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found[Search Provider] : hxxp://en.softonic.com/s/{searchTerms}[C:\Users\Gonalo\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found

    [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}[C:\Users\Joana.GONALO\AppData\Local\Google\Chrome\User Data\Default\Web data] -Found [Search Provider] : hxxp://www.softonic.com.br/s/{searchTerms}[C:\Users\Me\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] -Found [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof[C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://isearch.avg.com/search?cid={B7D183AF-CCD4-4E46-908F-DFE2C6E5F935}&mid=41310532646242b88aec138cbb106f63-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pt-br&ds=hk015&pr=sa&d=2013-04-27 14:53:52&v=15.5.0.2&pid=avg&sg=0&sap=dsp&q={searchTerms}

    *************************

    AdwCleaner[R0].txt - [15442 bytes] - [15/06/2015 09:16:20]AdwCleaner[R1].txt - [15501 bytes] - [15/06/2015 10:10:59]

    ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [15561 bytes] ##########